Malware

About “Bulz.523236” infection

Malware Removal

The Bulz.523236 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.523236 virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial language used in binary resources: Spanish (Peru)
  • The binary likely contains encrypted or compressed data.
  • Creates a hidden or system file
  • Anomalous binary characteristics

How to determine Bulz.523236?


File Info:

crc32: 2E3441D9
md5: 7cb193816262954c586cfd9d2b49e330
name: 7CB193816262954C586CFD9D2B49E330.mlw
sha1: cf46f3b90da47aa4abf0762ba9024e62be5e2563
sha256: 3d690f9d93bee5faa96b951b585788bfd4866bc2ebdffd2dabc1fa05865c2e61
sha512: c73e40fad6274968f78e2dbd4b27f3a41ef995bd9886706c945488d2b41583b2f21155cf9c48afd6c42a23b9c60ed6e1ecc076e3059c55027d417991853a5806
ssdeep: 24576:RhbI+OVCqdcOVHVCl8RRtJ4wJXLMgSFBDu48w7K5DhAR3Ujr3W9Iv:Y+7fhl8RRt3V3SFYAvIDz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translations: 0x48b6 0x0359

Bulz.523236 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Bulz.523236
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderGen:Variant.Bulz.523236
K7GWRiskware ( 0040eff71 )
APEXMalicious
KasperskyVHO:Trojan.Win32.Yakes.gen
MicroWorld-eScanGen:Variant.Bulz.523236
Ad-AwareGen:Variant.Bulz.523236
SophosML/PE-A + Troj/Kryptik-TR
BitDefenderThetaGen:NN.ZexaF.34758.gz0@aC8gzRSc
McAfee-GW-EditionBehavesLike.Win32.Lockbit.tc
FireEyeGeneric.mg.7cb193816262954c
EmsisoftGen:Variant.Bulz.523236 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Zenpak.hpk
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Azorult!ml
GDataGen:Variant.Bulz.523236
Acronissuspicious
MAXmalware (ai score=80)
VBA32BScope.Trojan.Crypt
MalwarebytesMachineLearning/Anomalous.95%
RisingMalware.Heuristic!ET#76% (RDMK:cmRtazosBihaiunwuOMhnrfxdat7)
IkarusTrojan.Win32.Ranumbot
MaxSecureTrojan.Malware.300983.susgen

How to remove Bulz.523236?

Bulz.523236 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment